Researchers disclose one-click ChatGPT Workspace Agents hijack, fixed by OpenAI in 4 days
rez0__ · x · 2026-07-23
- Researchers disclosed AgentForger, a cross-site agent forgery flaw in OpenAI’s ChatGPT Workspace Agents.
- The attack could let an adversary create a malicious autonomous agent inside a victim organization with one click, then chain actions such as app connection abuse, removing approvals, persistence, email C2, reconnaissance, data theft, impersonation, and wire fraud.
- The issue was reported to OpenAI via Bugcrowd, and OpenAI fixed it in four days.
- The researchers say the work was done with Zenity.
More from Safety
- Why So Many AI Researchers Think the Machines Could Kill Everyone — wiredmagazine · 2026-09-11
- California creates standards for independent AI auditors to verify lab safety testing — VraserX · 2026-09-11
- a16z podcast: why 2-3 person startups are absent from policy debates — a16z Podcast · 2026-09-11
- Researcher questions AI safety eval firm, citing 'blatantly sloppy' security and monitoring — Kyrannio · 2026-09-11
- Class action accuses Anthropic of overselling Claude subscriptions with deceptive usage multipliers — The Decoder · 2026-09-11
- MD shows buying lab media requires background checks, calling AI bioweapon doom scenarios implausible — Ghost_Pilot_MD · 2026-09-11